Technical Reference · 2026 Edition

bimi-email-authentication-guide

Last updated August 1, 2026 6 min read
yaml
---

title: "BIMI Email Authentication: The 2026 Guide" description: "The definitive guide to BIMI email authentication in 2026. Covers the latest requirements from Gmail, Apple Mail, and Yahoo." date: "2026-07-01"


BIMI Email Authentication: The 2026 Guide

Brand Indicators for Message Identification (BIMI) displays your verified logo directly in the inbox. Recipients see your brand before they open the message. Trust signals improve. Click rates improve. The mechanism is precise, standardized, and increasingly enforced.

This guide covers every technical layer required to deploy BIMI in 2026.


The Authentication Stack

BIMI sits at the top of an email authentication hierarchy. Every layer below must be solid before BIMI resolves.

SPF

Sender Policy Framework publishes authorized sending IPs in DNS. A passing SPF record is a prerequisite.

dns
v=spf1 include:_spf.example.com ~all

DKIM

DomainKeys Identified Mail applies a cryptographic signature to each outbound message. The receiving server validates the signature against a public key in DNS. DKIM must pass independently of SPF.

DMARC

Domain-based Message Authentication, Reporting, and Conformance ties SPF and DKIM to the From: domain. BIMI requires a DMARC policy of quarantine or reject. A policy of none is insufficient.

dns
v=DMARC1; p=reject; rua=mailto:[email protected]; ruf=mailto:[email protected]; pct=100

p=reject at pct=100 is the recommended baseline for full BIMI eligibility across all major clients in 2026.


The BIMI DNS Record

BIMI is published as a TXT record under the _bimi subdomain selector.

dns
default._bimi.example.com IN TXT "v=BIMI1; l=https:class="hl-cmt">//example.com/bimi-logo.svg; a=https://example.com/bimi.pem"

| Field | Value | Purpose | |---|---|---| | v | BIMI1 | Version identifier | | l | HTTPS URL | Points to the SVG logo | | a | HTTPS URL | Points to the VMC certificate |

The a= field is optional for clients that display BIMI without certificate verification. It is mandatory for Gmail and Apple Mail logo display in 2026.


SVG Requirements

The logo file must conform to the BIMI SVG Tiny Portable/Secure (SVG P/S) profile. Standard SVG files exported from Illustrator, Figma, or Sketch do not qualify without conversion. The spec prohibits scripts, external references, animations, and embedded raster images.

Specific constraints:

  • File must declare baseProfile="tiny-ps" and version="1.2" in the root element
  • Viewbox must define a square aspect ratio
  • No